5.3

CVSS4.0

CVE-2025-0788 - ESAFENET CDG content_top.jsp sql injection

A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /content_top.jsp. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the publ…

📅 Published: Jan. 28, 2025, 10:31 p.m. 🔄 Last Modified: May 16, 2025, 3:01 p.m.

5.3

CVSS4.0

CVE-2025-0787 - ESAFENET CDG appDetail.jsp cross site scripting

A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /appDetail.jsp. The manipulation of the argument curpage leads to cross site scripting. The attack can be launched remotely. The exploit has been…

📅 Published: Jan. 28, 2025, 10 p.m. 🔄 Last Modified: May 16, 2025, 3:02 p.m.

5.3

CVSS4.0

CVE-2025-0786 - ESAFENET CDG appDetail.jsp sql injection

A vulnerability was found in ESAFENET CDG V5. It has been classified as critical. Affected is an unknown function of the file /appDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public an…

📅 Published: Jan. 28, 2025, 10 p.m. 🔄 Last Modified: May 16, 2025, 3:01 p.m.

5.5

CVSS3.1

CVE-2024-29869 - Apache Hive: Credentials file created with non restrictive permissions

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgr…

📅 Published: Jan. 28, 2025, 9:31 p.m. 🔄 Last Modified: July 15, 2025, 4:28 p.m.

5.3

CVSS4.0

CVE-2025-0785 - ESAFENET CDG SysConfig.jsp cross site scripting

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing of the file /SysConfig.jsp. The manipulation of the argument help leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public …

📅 Published: Jan. 28, 2025, 9:31 p.m. 🔄 Last Modified: May 16, 2025, 3:01 p.m.

7

CVSS4.0

CVE-2025-24482 - FactoryTalk® View Site Edition - Local Code Injection

A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.

📅 Published: Jan. 28, 2025, 8:59 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-24481 - FactoryTalk® View Site Edition - Incorrect Permission Assignment

An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.

📅 Published: Jan. 28, 2025, 8:55 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.0

CVE-2025-24826 -

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.

📅 Published: Jan. 28, 2025, 8:46 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-0784 - Intelbras InControl Registered User usuario cleartext transmission

A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be …

📅 Published: Jan. 28, 2025, 8 p.m. 🔄 Last Modified: Aug. 20, 2025, 6:48 p.m.

8.4

CVSS3.1

CVE-2024-40677 -

In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…

📅 Published: Jan. 28, 2025, 7:13 p.m. 🔄 Last Modified: April 22, 2025, 2:28 p.m.
Total resulsts: 347742
Page 6779 of 34,775
« previous page » next page
Filters